Author Topic: Every scanner picks up a different infection  (Read 9528 times)

0 Members and 2 Guests are viewing this topic.

REDACTED

  • Guest
Every scanner picks up a different infection
« on: August 26, 2014, 01:01:44 AM »
Hello,
I’m seeing minor changes in my laptop’s behavior and every scan I’ve run so far has picked up something. Sorry in advance for all the details but I’m not sure what information is relevant.
Day 1 - Avast Pro notified me that a rootkit had been moved to the chest (I wasn’t online but the wifi was on so I’m assuming something got through there).
Day 2 - When I was logging into my laptop Lenovo’s security manager no longer required a password to log in (I got info that there was a problem connecting to the TPM). Also there was a problem with the previously automatic connection to the house wifi (the laptop could see the signal & the password had been input but there was a problem with the automatic acquiring of the network address so every day I have to go to wireless network connection and click that I want Windows to configure my settings). I run Avast boot time scan and it found 15 new infected files (all rootkits). 14 were moved to the chest, 1 could not be deleted or moved to chest b/c the file could not be found. Nothing else was done on the laptop that day.
Day 3 - run boot time scan and found 3 new infected files (2 were moved to chest, 1 could not be deleted or moved). No other activities were done on PC that day.
Day 4 run boot time scan and 0 infected files were found but about 3000 less files were tested than both previous times. I downloaded malwarebytes and that found 1 issue (it’s been quarantined). Spybot found 2 items that it categorized as malware/registry key/danger level 10/10 & malware/directory/danger level 10/10 – I quarantined those. AswMBR has also found a suspicious item.

Thanks in advance for all the help.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37626
  • Not a avast user
Re: Every scanner picks up a different infection
« Reply #1 on: August 26, 2014, 01:17:58 AM »
What is the full message from avast?
What file was detected ..... and location, full file path

Removal team is notified. Since it is midnight in europe they probably wont reply before tomorrow


Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Every scanner picks up a different infection
« Reply #2 on: August 26, 2014, 08:30:47 AM »
Hello,

Could you post the aswMBR.txt logreprot, scan results from standalone avast-gmer ARK tool?

I would like to see the avast! boot-time scan log as well. It is located here, post that as well.
C:\Documents and Settings\All Users\Application Data\AVAST Software\Avast\report\aswBoot.txt



1. Please download ComboFix by sUBs () from here and save it to your Desktop.
If you are unsure how ComboFix works, read this guide.

--------------------------------------------------------------------
2. Temporarily disable your AntiVirus program, usually via a right click on the System Tray icon. They may interfere with Combofix.
If you are unsure how to do this please read this or this Instruction.

Instructions how to disable avast:
• Right click on the avast! system tray icon () in the lower right corner of the screen and scroll up to avast! shield controls;
• In the menu that appears, choose Disable Permanently. When you are prompted to turn off security, click Yes.

Note:  Do not forget to turn back on this option after the cleaning by choosing avast! shield controls > Enable all shield options.


--------------------------------------------------------------------
3. Run ComboFix. Then, on disclaimer window, click I Agree! button.

- ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.

-If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
- ComboFix will scan your computer in stages, total of 50 stages.
Do not mouse-click around while ComboFix is running.
- If malware is detected, ComboFix will begin with its removal, and may need to restart Windows.
Note:If you see a message like "Illegal operation attempted on a registry key that has been marked for deletion" just restart your computer.

--------------------------------------------------------------------
4. When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt)
=> Attach log report (ComboFix.txt) back to topic.

ComboFix shall also create addition log (typical location: C:\Qoobox\ComboFix-quarantined-files.txt)
=> Please attach that report (ComboFix-quarantined-files.txt) as well.

REDACTED

  • Guest
Re: Every scanner picks up a different infection
« Reply #3 on: August 26, 2014, 12:23:51 PM »
I’m attaching the aswMBR file (I didn't quarantine the suspicious item)  and aswBoot scan.
While the actual boot scan report says that ALL the infections were moved to the chest, the scan results on the avast screen say something different. For the july 01 scan 15 files were found as infected – 14 were moved to chest, 1 could not be found. For the July 02 scan 3 files were found as infected – 2 were moved to chest, 1 could not be found. I’ve attached a pic to demonstrate what I mean.
I’m also attaching an avast file system shield report b/c after the last boot scan on 07/22  avast has moved new items to be quarantined with a similar location (C:\System Volume Information\_restore{A8393674-085C-4723-B63E-39928C5F4C89}…..).
I will download Combofix now and send the log as soon as it’s available.

REDACTED

  • Guest
Re: Every scanner picks up a different infection
« Reply #4 on: August 26, 2014, 12:49:03 PM »
Avast blocked the download of Combofix from bleepingcomputer.com & moved it to chest (C:\Documents and Settings\Admin\Local Settings\Temp\ZYgahW3N.exe.part [L] Win32:Dropper-gen [Drp] )

Am I supposed to disable Avast before I download Combofix or before I run it?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37626
  • Not a avast user
Re: Every scanner picks up a different infection
« Reply #5 on: August 26, 2014, 12:56:32 PM »
Yes .... Right click avast tray icon and pause shields

REDACTED

  • Guest
Re: Every scanner picks up a different infection
« Reply #6 on: August 26, 2014, 02:12:24 PM »
Combofix scans

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Every scanner picks up a different infection
« Reply #7 on: August 27, 2014, 01:07:51 PM »
We shall run ComboFix one more time, and this time we will use CFScript for that running.  Open notepad and copy/paste the text present inside the code box below:


Code: [Select]
FileLook::
C:\WINDOWS\System32\DLA\DLADResN.SYS

ClearJavaCache::

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000000

Save this as CFScript.txt



Close all browser windows and refering to the picture above.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:\ComboFix.txt )






.







I would also like to preform the additional ARK system scan and we will use MBAR for that check. Please download Malwarebytes AntiRootkit (MBAR) and save it to your desktop.
For full instructions how MBAR works, read this article


> Doubleclick on the MBAR file () and allow it to run.
•  Click OK on the next screen, to allow the package to extract the contents of the file to its own folder named mbar.
•  mbar.exe will launch automatically. On some systems, this may take a few extra seconds. Please be patient and wait for the program to open.
•  After reading the Introduction, click Next if you agree.


•  On the Update Database screen, click on the Update button. Once you see 'Success: Database was successfully updated' click on Next
•  Under Scan Targets ensure all boxes are ticked. Then click the Scan button.

Notice: with some infections, you may see two messages boxes:
'Could not load protection driver'. Click 'OK'.
'Could not load DDA driver'. Click 'Yes' to this message, to allow the driver to load after a restart. Allow the computer to restart. Continue with the rest of these instructions.


>>  If malware is not detected, click the Exit button to close the program and post the mbar-log-year-month-day.txt and system-log.txt reports.

>>  If an infection/s are found ensure Create Restore Point are ticked. Then select the "Cleanup! button to remove threats.
•  The clean up procedure will be scheduled for process, pop-up will be shown.
Select the Yes button and the system should re-boot to complete the cleaning process.


>>  Notice: only if an RootKit are detected, ensure to run fixdamage.exe tool located in mbar folder, \Plugins\fixdamage.exe
- Run fixdamage.exe, at the black window to continue type Y (alias for Yes). Wait few seconds for execution ...
- When you see "press any key to exit" fix is completed, press any key to close the window. Reboot the system.





> The following reports will be created in mbar folder:
1. mbar-log-year-month-day (hour-minute-second).txt
2. system-log.txt



Please post both MBAR's logs in your next reply along with fresh created ComboFix.txt.



REDACTED

  • Guest
Re: Every scanner picks up a different infection
« Reply #8 on: August 27, 2014, 05:50:42 PM »
Im having a problem with Combofix.
I copied the code to the notepad and tried dragging CFScript.txt into ComboFix.exe but I get an error message. I redownloaded Combofix & get same error msg. Pic attached.

REDACTED

  • Guest
Re: Every scanner picks up a different infection
« Reply #9 on: August 27, 2014, 08:33:07 PM »
MBAR logs

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Every scanner picks up a different infection
« Reply #10 on: August 27, 2014, 10:32:02 PM »
Could you now reset (turn off and on) your system restore? Follow these manual:
http://support.microsoft.com/kb/310405


Im having a problem with Combofix.
I copied the code to the notepad and tried dragging CFScript.txt into ComboFix.exe but I get an error message. I redownloaded Combofix & get same error msg.

Could you just post the fresh FRST logs insted? And tell me do you still getting the avast! alearts?

REDACTED

  • Guest
Re: Every scanner picks up a different infection
« Reply #11 on: August 27, 2014, 11:06:34 PM »
Ive reset my system restore and attached FRST logs.

I'm not sure which Avast alerts you are referring to - if the question is: has anything new been added to the chest in the last 2 days then 'no", if the question is: does avast alert/block me while im browsing online then im not sure b/c I haven't been paying attention, if you are asking if I'm getting alerts while opening eg. combofix then "yes". 

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Every scanner picks up a different infection
« Reply #12 on: August 27, 2014, 11:13:21 PM »
I'm not sure which Avast alerts you are referring to - if the question is: has anything new been added to the chest in the last 2 days then 'no", if the question is: does avast alert/block me while im browsing online then im not sure b/c I haven't been paying attention

That is good answare. The following shall just preform some small (post cleaning) fix ...




1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Code: [Select]
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1060933&SSPV=IENOSGBR
EmptyTemp:

2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.


3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.


REDACTED

  • Guest
Re: Every scanner picks up a different infection
« Reply #13 on: August 27, 2014, 11:37:38 PM »
newest scan  :D

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Every scanner picks up a different infection
« Reply #14 on: August 28, 2014, 12:12:29 AM »
Hi,

No I do not need new scan. I need you to create the fixlist.txt with above code and execute that scrpt by pressing Fix button in FRST's GUI.
Apon execution the script (fixlist) tool shall create a new report with name fixlog.txt. Post that here.  ;)